Sept. 15, 2023, 4:26 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

When you need to change the prototype of a function in the decompiler, the standard way is to use the “Set item type…” action (shortcut Y).



One case where you may need to do it is to add or remove arguments. Especially in embedded code or when decompiling variadic functions, the decompiler may deduce the argument list wrongly. A good test for bogus arguments is to check whether they’re referenced in the function’s body. For this, use “Jump to xref” …

action case change code decompiler decompiling embedded function malware analysis may prototype remove standard week

Security Specialist

@ Nestlé | St. Louis, MO, US, 63164

Cybersecurity Analyst

@ Dana Incorporated | Pune, MH, IN, 411057

Sr. Application Security Engineer

@ CyberCube | United States

Linux DevSecOps Administrator (Remote)

@ Accenture Federal Services | Arlington, VA

Cyber Security Intern or Co-op

@ Langan | Parsippany, NJ, US, 07054-2172

Security Advocate - Application Security

@ Datadog | New York, USA, Remote